collapse

Search


User Info

 
 
Welcome, Guest. Please login or register.
Did you miss your activation email?

Author Topic: ACS 5.5.0.46.7 - Issues with 802.1x Binary Cross Check to AD on 2012R2  (Read 13992 times)

Offline goat1803

  • Cisco Newbie
  • *
  • Posts: 1
  • Reputation: 0
  • Certification: N/A
 I have ACS serving as the authentication server in a cert based 802.1x setup, trying to authenticate EVGA PD07 zero clients to my lab AD domain utilizing EAP-TLS.

I've set up NDES services, pushing .pem certificates to my zero clients via SCEP.  I haven't configured auto enroll yet, so I manually issue the cert from the CA, and then export the issued cert (.cer) to a file.  From there, I publish the cert with a user object in AD.

 

I have the client cert / CA loaded correctly on ACS, all of the LDAP is working as far as querying groups and such is concerned, and I can authenticate the presented zero client certificate against the AD published cert using the Common Name attribute.  The only thing that doesn't work is Binary Cross Check.  The logs throw a 22056 error (subject not in applicable identity store) and reject the attempt.  As soon as I go in to the authentication profile and disable the cross check, it authenticates successfully.

 

any ideas?

 

Offline MC

  • Global Moderator
  • Cisco Guru
  • *****
  • Posts: 401
  • Reputation: 606
  • CCIE x3 (RS,Sec,SP)
  • Certification: CCIE
Re: ACS 5.5.0.46.7 - Issues with 802.1x Binary Cross Check to AD on 2012R2
« Reply #1 on: December 12, 2014, 12:00:56 AM »
Can you please elaborate on how you actually get the cert on the client, and also what you mean by publish the cert with user object in AD? What is the problem with having the binary check disabled? Is it for security reason or something else?

 

Related Topics

  Subject / Started by Replies Last post
15 Replies
36838 Views
Last post September 20, 2013, 10:02:32 PM
by MC
5 Replies
56653 Views
Last post October 11, 2014, 05:10:57 AM
by adecisco
5 Replies
21897 Views
Last post April 13, 2014, 09:10:08 AM
by MC
1 Replies
25869 Views
Last post June 05, 2015, 09:03:41 PM
by MC

SimplePortal 2.3.7 © 2008-2024, SimplePortal